Ross ROSS = Recommend OSS · open-source software intelligence for agents

kanidm/kanidm

Kanidm: A simple, secure, and fast identity management platform observed · 2026-08-28

github.com/kanidm/kanidm · homepage · Rust · MPL-2.0 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

99/100

  • Activity 99
  • Release rhythm 98
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 8
  • age_days: 2770
  • days_rel: 19
  • days_push: 7
  • n_releases_24m: 38

Full methodology

Adoption not part of the score

5291 stars · 354 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

Kanidm is a simple, secure, and fast identity management platform written in Rust that acts as a complete identity provider for other applications and services. It bundles OAuth2/OIDC SSO, WebAuthn passkeys, LDAP gateway, RADIUS, SSH key distribution, and Unix integration into a single self-hosted service.

Use cases

  • self-host an SSO identity provider with OAuth2/OIDC
  • replace Keycloak with a simpler identity management platform
  • enable passkey/WebAuthn login for my applications
  • manage Linux/Unix user accounts and SSH keys centrally
  • provide RADIUS authentication for VPN and network access
  • serve LDAP for legacy applications
  • run identity management for a homelab or small business

When to choose

  • you want a complete identity provider with OAuth2/OIDC built in, without needing Keycloak
  • you want passkeys/WebAuthn and strict security defaults out of the box
  • you need Linux/Unix integration, SSH key distribution, or RADIUS alongside SSO
  • you find FreeIPA too heavy and complex but want more than a bare LDAP server

When to avoid

  • you only need a minimal LDAP server and prefer something simpler like LLDAP
  • you need deep LDAP customization or a generic directory server like OpenLDAP/389-ds
  • you require Kerberos or a full FreeIPA feature set such as DNS and certificate authority

Facets

service · maturity active

auth authorization security self-hosted cli developer-tools security self-hosted developer-tools backend rust self-hosted identity-management oidc oauth2 webauthn passkeys ldap sso radius scim ssh-keys iam linux macos docker web-server

4 sources

Member repositories

RepositoryRoleHealth v2
kanidm/kanidmmain99

For agents

markdown · JSON · MCP: product_card(name="kanidm/kanidm")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem